The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.
                
            References
                    | Link | Resource | 
|---|---|
| http://support.apple.com/kb/HT5704 | Vendor Advisory | 
| http://lists.apple.com/archives/security-announce/2013/Mar/msg00005.html | Vendor Advisory | 
| http://support.apple.com/kb/HT5702 | Vendor Advisory | 
| http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.html | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Information
                Published : 2013-03-20 07:55
Updated : 2019-09-26 10:05
NVD link : CVE-2013-0978
Mitre link : CVE-2013-0978
JSON object : View
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
                apple
- iphone_os
- tvos


